NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 2239 | CVE-2008-2318 | The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remote attackers to obtain potentially sensitive information by reading the requests for these URLs. | 2 | 5 | Medium | 2017-01-03 | 2011-03-07 | View | |
| 36287 | CVE-2014-9668 | The woff_open_font function in sfnt/sfobjs.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting length values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Web Open Font Format (WOFF) file. | 2 | 7.5 | High | 2017-01-19 | 2017-01-02 | View | |
| 37636 | CVE-2013-1431 | The Wocky module in Telepathy Gabble before 0.16.6 and 0.17.x before 0.17.4, when connecting to a "legacy Jabber server," does not properly enforce the WockyConnector:tls-required flag, which allows remote attackers to bypass TLS verification and perform a man-in-the-middle attacks. | 2 | 6.8 | Medium | 2017-01-18 | 2016-11-08 | View | |
| 77628 | CVE-2001-0148 | The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
| 23278 | CVE-2015-0844 | The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbitrary files via a crafted (1) campaign or (2) map file. | 2 | 5 | Medium | 2017-01-19 | 2016-06-28 | View |
Page 2638 of 17672, showing 5 records out of 88360 total, starting on record 13186, ending on 13190